T09 · Insecure Skill Coding Practices
- Location
frameworks.md:65- Finding
Next.js protected-route template accepts an unverified authentication cookie
- Content
View full analysis
Vulnerability Details
File Location:
frameworks.md, lines 65–70
Vulnerability Type: Authentication bypass through missing token verification
Risk Level: HighVulnerable code:
ts const token = request.cookies.get("cloudbase_token")?.value if (!token) { return NextResponse.json({ error: "Unauthorized" }, { status: 401 }) } // Verify token with Node SDK or forward to your backend return NextResponse.json({ data: "protected resource" })Technical Analysis
The documented Next.js route checks only whether the
cloudbase_tokencookie contains a non-empty value. Although a comment says to verify the token, the shown execution path performs no cryptographic signature, issuer, audience, expiration, session, or revocation validation before returning protected data.Because HTTP cookies are controlled by the requesting client, the existence check cannot establish an authenticated identity. A coding agent following this template could generate a purportedly protected API route in which arbitrary remote clients are treated as authenticated.
The trust boundary is crossed when an attacker-controlled cookie is accepted by server-side authorization logic without authoritative verification.
Attack Path
- A developer or coding agent implements a protected Next.js route using the documented template.
- A remote attacker sends a request to that route with any non-empty cookie, for example
cloudbase_token=invalid. - The route passes the presence check because the cookie exists.
- No token-verification operation is performed.
- The route returns the protected response to the unauthenticated attacker.
Impact Assessment
An attacker can bypass authentication for endpoints implemented using this pattern. The resulting privileges depend on the operations placed behind the route and may include unauthorized access to application data or invocation of authenticated state-changing actions ...[truncated 107 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the cookie-presence check with an authoritative server-side token or session verification operation.
- Validate the token signature, issuer, audience, expiration, and required scopes or claims.
- Check session revocation where the authentication platform supports it.
- Derive the request identity exclusively from verified claims rather than from the raw token.
- Fail closed when verification is unavailable, returns an error, or produces an invalid result.
- Replace the current example with a complete secure implementation; do not represent a verification comment as an implemented security control.
- Add tests proving that missing, malformed, forged, expired, and incorrectly issued tokens receive an unauthorized response.
